automation-recon-pipeline

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for bug-bounty automation, but it gives an AI agent offensive recon/scanning capability and encourages unattended continuous execution. Install trust is mostly acceptable for official ProjectDiscovery tools, with moderate residual supply-chain risk from unpinned installs and the third-party `anew` utility. No clear credential harvesting or covert exfiltration is present.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:02 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fautomation-recon-pipeline%2F@b0947b0e0201cb40545ee9ba0bd15665de430c949e5657936d4b0606184ffacb
Security Audit — socket — automation-recon-pipeline